<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User having issues accessing internet after connecting to Global Protect -- Userid in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-having-issues-accessing-internet-after-connecting-to-global/m-p/576855#M4955</link>
    <description>&lt;P&gt;Hi Team&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are seeing an issue where only 1 user is having issues when going to any websites over Global Protect. DNS lookup completes and the built-in Apps like Outlook, teams work over GP with no issues. The user is able to successfully authenticate with DUO MFA, the issue is only after the connection with GP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We can see that the client is being identified as "domain\username" in Monitor &amp;gt; Traffic logs when the client is having issues accessing the website using the web browser.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But under monitor &amp;gt; traffic logs when the same user is identified as just "username" on the firewall we can see that she was able to access Outlook/Teams.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In checking authd.log when she connects with DUO MFA, we can see teh client is recognized just as "username". We would like to understand why sometime firewall is seeing the user as&amp;nbsp;"domain\username" and sometimes "username" only.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Under Policy we have "Any" so nothing gets dropped on Firewall but still client is not able to access the websites. All other working users are being identified as "username" and no one have any issues. Already tried to clear user-mapping but this did not help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Username Modifier is set to %USERINPUT%.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there anything we can check or make sure that the user-id would be consistent or to understand why this is happening with 1 user only.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="GlobalProtect" id="GlobalProtect"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Feb 2024 17:15:27 GMT</pubDate>
    <dc:creator>UtkarshKumar</dc:creator>
    <dc:date>2024-02-09T17:15:27Z</dc:date>
    <item>
      <title>User having issues accessing internet after connecting to Global Protect -- Userid</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-having-issues-accessing-internet-after-connecting-to-global/m-p/576855#M4955</link>
      <description>&lt;P&gt;Hi Team&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are seeing an issue where only 1 user is having issues when going to any websites over Global Protect. DNS lookup completes and the built-in Apps like Outlook, teams work over GP with no issues. The user is able to successfully authenticate with DUO MFA, the issue is only after the connection with GP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We can see that the client is being identified as "domain\username" in Monitor &amp;gt; Traffic logs when the client is having issues accessing the website using the web browser.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But under monitor &amp;gt; traffic logs when the same user is identified as just "username" on the firewall we can see that she was able to access Outlook/Teams.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In checking authd.log when she connects with DUO MFA, we can see teh client is recognized just as "username". We would like to understand why sometime firewall is seeing the user as&amp;nbsp;"domain\username" and sometimes "username" only.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Under Policy we have "Any" so nothing gets dropped on Firewall but still client is not able to access the websites. All other working users are being identified as "username" and no one have any issues. Already tried to clear user-mapping but this did not help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Username Modifier is set to %USERINPUT%.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there anything we can check or make sure that the user-id would be consistent or to understand why this is happening with 1 user only.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="GlobalProtect" id="GlobalProtect"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 17:15:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-having-issues-accessing-internet-after-connecting-to-global/m-p/576855#M4955</guid>
      <dc:creator>UtkarshKumar</dc:creator>
      <dc:date>2024-02-09T17:15:27Z</dc:date>
    </item>
  </channel>
</rss>

